logo

State-backed hackers are exploiting new Ivanti VPN zero-days — but no patches yet

ID: 2624a48b-f339-5935-9459-69d32c810483

STIX ID: report--2624a48b-f339-5935-9459-69d32c810483

Feed Name: TechCrunch Security News

Threat Score
88/100

Date Published: 2024-01-11

Date Updated: 2026-04-23

Author: Carly Page

...
...

Ivanti has confirmed active exploitation of two critical zero-day flaws in its Connect Secure VPN appliances that allow unauthenticated remote code execution; vendor patches are delayed while CISA and researchers urge immediate mitigations. Volexity links observed intrusions to a China-backed group (UTA0178) and notes potential compromises dating to early December, and scans suggest roughly 15,000 internet-exposed appliances may be vulnerable, increasing the risk of widespread impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.